Turn critical SonarCloud findings into tracked Jira tickets

By General Input

Only blocker and critical bugs and vulnerabilities become Jira tickets, with the file, the rule, why it matters, and a suggested fix.

Integrations

  • SonarCloud
  • Jira
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering

When a new issue is raised in my SonarCloud organization, I want it triaged automatically instead of piling up in the Sonar UI where nobody looks. Use the SonarCloud poll trigger for a new issue in the organization so this runs on each fresh finding rather than on a schedule.

First, use SonarCloud "Issues — Search" to pull the full context for the finding: the issue key, the rule key, the severity, the issue type, the project and component it belongs to, the file path, the line number, the issue message, and the code author. Then use SonarCloud "Rules — Show" with that rule key to fetch the rule name, the rule description, and the remediation guidance Sonar publishes for it.

Now judge whether the finding deserves a ticket. Only escalate issues that are BLOCKER or CRITICAL severity AND that are bugs or vulnerabilities. Skip code smells entirely, and skip anything at MAJOR, MINOR or INFO severity. Most findings should end here with no ticket and no Slack message. That restraint is the whole point: the backlog only stays credible if it holds genuine problems, and teams routinely drown in low severity code smells while real blockers sit unnoticed. If the finding does not clear the bar, stop the run quietly.

Before creating anything, use Jira "Search Issues (JQL)" to check whether this finding has already been filed. Search my engineering project for the SonarCloud issue key in the ticket text, for example: project = ENG AND text ~ "<sonarcloud issue key>". This step is essential because a single unfixed SonarCloud issue reappears on every analysis run, so without it the same finding would be filed again and again. If a matching ticket already exists, stop and do not create a duplicate.

If nothing matches, use Jira "Create Issue" to open a Bug in my engineering project. Put the rule name and the offending file in the summary. In the description include: the file path, the line number, the rule name and rule key, the severity and issue type, the component, the code author who last touched that file, a plain language explanation of why this matters (write it from the rule description rather than pasting the raw text), a suggested fix based on the remediation guidance, and the SonarCloud issue key so later runs can dedupe against it. Call out the component and the code author explicitly so whoever triages the board can route the ticket to the right person.

Finally, use Slack Bot "Send a Message" to post a short note to my team channel. Keep it to a couple of lines: the rule name, the severity, the file and line, and links to both the new Jira ticket and the original SonarCloud issue. This is a heads up rather than a full report, since all the detail already lives on the ticket.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them